2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24081 | HIGH | 7.8 | 0.7% | Mar 11, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-24080 | HIGH | 7.8 | 0.7% | Mar 11, 2025 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-24079 | HIGH | 7.8 | 0.7% | Mar 11, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-24078 | HIGH | 7 | 0.5% | Mar 11, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-24077 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-24076 | HIGH | 7.3 | 3.0% | Mar 11, 2025 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24075 | HIGH | 7.8 | 0.6% | Mar 11, 2025 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-24072 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges... |
| CVE-2025-24070 | HIGH | 7 | 0.9% | Mar 11, 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2025-24067 | HIGH | 7.8 | 0.7% | Mar 11, 2025 | Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24066 | HIGH | 7.8 | 0.7% | Mar 11, 2025 | Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24064 | HIGH | 8.1 | 1.3% | Mar 11, 2025 | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24061 | HIGH | 7.8 | 1.1% | Mar 11, 2025 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feat... |
| CVE-2025-24059 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to ele... |
| CVE-2025-24057 | HIGH | 7.8 | 0.9% | Mar 11, 2025 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| CVE-2025-24056 | HIGH | 8.8 | 1.6% | Mar 11, 2025 | Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. |
| CVE-2025-24051 | HIGH | 8.8 | 1.5% | Mar 11, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut... |
| CVE-2025-24050 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24049 | HIGH | 8.4 | 0.4% | Mar 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (C... |
| CVE-2025-24048 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24046 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24045 | HIGH | 8.1 | 1.4% | Mar 11, 2025 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to... |
| CVE-2025-24044 | HIGH | 7.8 | 0.5% | Mar 11, 2025 | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. |
| CVE-2025-24043 | HIGH | 7.5 | 0.9% | Mar 11, 2025 | Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. |
| CVE-2025-24035 | HIGH | 8.1 | 1.7% | Mar 11, 2025 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now